It is an uncomfortable but common question for growing professional firms: did the person who left three weeks ago still have access to anything?
In a small consultancy, agency, accountancy practice or advisory firm, offboarding often starts as a simple checklist. Remove email access. Collect the laptop. Tell payroll. Ask the line manager to organise handover.
As the business grows, the checklist becomes harder to trust. Staff may have access to shared drives, client portals, CRM systems, finance software, proposal folders, password managers, project tools, marketing platforms, messaging apps and specialist systems linked to their role. Some of those accounts are managed by IT. Some are owned by operations. Some sit with a partner who set them up two years ago and forgot they existed.
That is where a carefully designed assistant can help. Not by revoking access on its own, but by generating, assigning and chasing a role-specific offboarding checklist so nothing important is left to memory.
The problem: offboarding is often spread across too many heads
Most firms are reasonably good at welcoming new people. There is a laptop, an email account, software access and a first-week plan.
Offboarding can be less tidy. It often happens during a busy handover period, sometimes with emotion attached, and sometimes with a leaver moving to a competitor or a client-side role. HR, IT, finance and the line manager may all own different parts of the process.
That fragmentation creates risk. Lingering access is not just untidy admin. It can become a security issue, a client confidentiality issue and, for regulated firms, a compliance concern.
An example workflow: a role-specific offboarding assistant
This is an example workflow, not a real client case study.
Imagine an accountancy practice has a maintained reference list of the systems typically used by each role. A client manager might have access to email, the CRM, document storage, practice-management software, client bookkeeping platforms and selected client portals. A marketing executive might have access to the website, social scheduling tools, analytics and design software.
When HR records a leaver, the assistant receives a few basic inputs:
- the person’s role;
- their team;
- their last working day;
- and any existing offboarding template.
Using the role-access reference list, the assistant generates a tailored checklist. Each item has an owner and a deadline tied to the last working day. For example:
- IT: disable email account by 5pm on last working day;
- IT: remove shared-drive and client-folder access;
- line manager: confirm knowledge handover completed;
- finance: reclaim paid software licences;
- operations: confirm laptop and equipment returned;
- client lead: remove access to named client systems where applicable.
The checklist can live in a task-tracking tool, shared checklist or HR workflow. The assistant then chases overdue items automatically and produces a final sign-off report showing what was completed, by whom and when.
The assistant tracks and chases. People still confirm.
This is the most important guardrail.
An offboarding assistant should not simply mark access as removed because a deadline passed. It should not pretend to know an account was disabled unless a named person confirms it. For a security-sensitive workflow, “probably done” is not good enough.
The assistant’s job is to make the work visible:
- what needs doing;
- who owns it;
- when it is due;
- what is overdue;
- and what still needs sign-off.
The IT or HR lead remains responsible for confirming completion and signing off the final report.
Why this is a good AI use case
This is not glamorous AI. It will not produce a dramatic demo. But it is exactly the kind of practical workflow where AI can be useful for a growing firm.
The assistant can interpret role information, generate a tailored checklist from a maintained reference, adjust deadlines based on the leaver’s final day, draft chase messages, and summarise the final audit trail.
That can save 30 to 60 minutes of coordination per leaver, particularly where HR and IT are chasing each other by email. More importantly, it reduces the chance of a forgotten access-revocation step.
The reference list is the heart of the system
The automation is only as good as the role-access reference behind it. If the list is out of date, the checklist will be incomplete.
For that reason, the reference should be reviewed regularly. When a new system is introduced, it should be added. When a role changes, its access profile should be updated. When an offboarding checklist catches something unexpected, the reference list should be improved for next time.
This is also where a simple first version can work well. You do not need to integrate with every system on day one. You can start by creating better checklists and better chasers, then decide later whether deeper integrations are justified.
A practical next step
Choose one role in your firm and write down every system that person can access. Include obvious tools, client systems, shared folders, licences, devices and any informal workarounds. Then compare that list with your current offboarding checklist.
If there is a gap, you have found a useful automation opportunity.
If your business wants a safer, less memory-dependent offboarding process, I can help you map the workflow, build a role-access reference and design a human-approved AI assistant that tracks, chases and reports without taking risky action on its own. Book a short call or describe your current offboarding problem, and we can sketch a sensible first version.